ZeroHour
Help Net Securitypublished ()ingested Sinisa Markovic1

IT help-desk vishing tricks executives into handing over Microsoft 365 access

highThreat actor exploited in the wildimportance 68
AI summary · glm-5.3-flash

Arctic Wolf tracks PREY-0058 (linked to UNC6671), a vishing campaign stealing Microsoft 365 session tokens via AiTM panels for SaaS data theft and extortion.

Arctic Wolf is tracking a campaign, PREY-0058, sharing tradecraft with Google Threat Intelligence Group's UNC6671, in which callers posing as internal IT talk employees through fake passkey/MFA setups. Operator-controlled adversary-in-the-middle pages harvest passwords and MFA approvals to seize session tokens, then actors enumerate and bulk-exfiltrate data from SharePoint, OneDrive, Exchange, and Box. Extortion brands include BlackFile, Pink, Helix, Cinder, and Redact; targets are mostly US-based executives in construction, healthcare, real estate, finance, and professional services, with exfiltration shifting to residential proxies like NodeMaven.

  • Vishing calls lead to manually gated AiTM panels capturing session tokens
  • Attackers pivot to My Sign-ins/My Profile, then sweep SharePoint site by site
  • Exfiltration IPs shifted from datacenter ASNs to the same residential proxy network (NodeMaven)
  • Cinder assessed as continuation of Pink based on overlapping victims and infrastructure
  • Mitigations: phishing-resistant MFA, conditional access blocking proxy traffic, help-desk training
Full article525 words · extracted from helpnetsecurity.com · click to collapse

IT help-desk vishing calls, stolen session tokens, and sign-ins routed through residential proxies are behind a wave of data theft and extortion against Microsoft 365 and other SaaS accounts, according to Arctic Wolf.

Microsoft 365 vishing

The company is tracking the activity under the name PREY-0058 and notes it shares significant tradecraft similarities with a data extortion group that Google Threat Intelligence Group calls UNC6671.

The extortion side has gone by several names, among them BlackFile, Pink, Helix, Cinder and Redact. Researchers wrote that the labels “may represent affiliates, changing brands, or other relationships rather than a single proven actor identity.”

They assess with moderate confidence that Cinder is a continuation of Pink, since victims listed on the Cinder leak site overlap with organizations previously hit by Pink-linked phishing infrastructure.

“Analysis of subdomains across the lure infrastructure revealed hundreds of entries impersonating real companies. The targets are primarily US-based and concentrated in construction and engineering, healthcare and pharmaceuticals, real estate and property management, finance, and professional services,” Arctic Wolf said.

“These attacks most frequently target Directors, Vice Presidents, and other executive staff.”

How the calls work

The attack starts with a phone call from a person claiming to be internal IT, who walks the employee through what sounds like routine passkey or MFA setup, then sends a link to an authentication page dressed up to look like it belongs to the victim’s own company, often hosted as a subdomain carrying the company’s name.

Behind that page is an operator-controlled adversary-in-the-middle (AiTM) panel, manually gated for each victim, which stages the Microsoft 365 login flow, catches the password and MFA approval, and uses them to pull an authenticated session token.

Once inside, the attackers open pages like My Sign-ins, My Profile and My Apps first, which lay out the account’s details and the list of applications tied to it. From there they search through SharePoint site by site and page by page, working systematically through the results to map out what’s stored there before anything is copied.

In the final step, the threat actors perform bulk collection and exfiltration from SharePoint, OneDrive, Exchange and other SaaS providers such as Box.

“Observed Exchange collection generates MailItemsAccessed events, while SharePoint and OneDrive collection produces high volumes of FileAccessed and FileDownloaded events. The client IP addresses used in exfiltration have typically resolved to datacenter/hosting infrastructure, but more recently have shifted to using the same residential proxy network that was used for initial access, such as NodeMaven,” Arctic Wolf explained.

What organizations can do

Arctic Wolf advises organizations to tighten Conditional Access so proxy and hosting traffic gets blocked or challenged, swap in phishing-resistant MFA that can’t be relayed through a fake login page, cut down how much a single SharePoint account can reach, and train help-desk staff to spot a vishing call.

“Defenders can disrupt this activity by detecting anomalous residential-proxy token replay, SharePoint discovery and bulk access, mailbox harvesting, and newly registered authentication-themed lure infrastructure,” they added.

Arctic Wolf also published indicators of compromise, including lure domains, exfiltration ASNs, and the residential proxy providers tied to sign-in activity, for organizations that want to check their own logs against this cluster.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/09/08/vishing-microsoft-365-data-theft-extortion/